[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#2597: checksums needed for entire distribution



Package: Debian Linux itself(?)
Version: ?

Hi,

A suggestion: the Debian distributions on ftp.debian.org should include
              a complete manifest of file checksums at their top levels.
              (e.g. md5sum `find . -type f` )

This would allow the integrity of the distribution to be maintained
across mirrors. With such a large amount of data, errors in transfers
are inevitable. Only CRCs can protect against them.

Some of the files on Yggdrasil's current Winter 96 Debian CD are
corrupt because of undetected errors (after talking to them today they
are working on a fix and have just annouced a "recall"). [Only a
handful of bits were flipped but the emacs, groff and gcc .debs took
the hits badly and would not install.]

The people at Yggdrasil were not familiar enough with dpkg to use it
to check their master CD, and they don't do installations of all the
distributions on their Internet Archive CDs so they never caught the
errors (i.e. the gzip crc in the .deb files did not help unfortunately).

I hope you agree that CRC Manifests would be A Good Thing(tm).

If so, the question is "Which type? sum, cksum or md5sum?"

I think the best answer is "all of them"!

Perhaps in files like MANIFEST.sum MANIFEST.cksum MANIFEST.md5sum at
the top level. That way every redistributor and mirror site could
easily verify their copy of the files before pressing their CDs and
selling them.

best regards

--
Brian Gough

bjg@fnal.gov
http://www-theory.fnal.gov/people/bjg/gough.html



Reply to: